Description
When an nginx web server implements an HTTP redirect by using the $uri or $document_uri variables within the redirection target location, the resulting configuration may be vulnerable to header injection.
Remediation
Implement the HTTP redirect with $request_uri instead of $uri or $document_uri.
References
Related Vulnerabilities
WordPress Plugin The Events Calendar Cross-Site Scripting (3.0)
WordPress Plugin QueryWall:Plug'n Play Firewall Cross-Site Scripting (1.1.0)
WordPress Plugin Clockwork SMS Notfications Cross-Site Scripting (2.0.3)
WordPress Plugin MainWP Dashboard Cross-Site Scripting (3.1.2)
WordPress Plugin Car Rental System Cross-Site Scripting (1.3)